BabySOARus Support

How to get help, what we cover, and how quickly we respond. This page is the "channels we publish" that section 7.1 of the Terms of Service refers to.

How to Reach Us

Email support@hisn.io. That is the whole of it: no portal, no account to create, no ticket number to quote back at us.

For anything about billing, renewals or cancellation, the same address is fine. For data protection, privacy@hisn.io; for anything contractual, legal@hisn.io.

What to Include

A good report gets a real answer on the first reply instead of the third. Please send:

  • What you did, what happened, and what you expected instead. The search, the function name, or the exact steps.
  • The error message, in full, copied rather than described.
  • Your BabySOARus version and Splunk version. | exec inline="pass" will name the version in the search log, and the app's version is in app.conf.
  • What licence.status says, if the problem might be licensing -- the Licence page in the app shows it.
  • The daemon log if the daemon is involved: $SPLUNK_HOME/etc/apps/babysoarus/var/daemon.log.

Please do not send us your event data. We do not need it, we do not want to hold it, and a redacted example of the shape is more useful than a real extract. If a problem genuinely cannot be reproduced without real data, we will say so and agree how to handle it first.

Response Times

Acknowledgement Within one business day
Business hours 09:00-17:30 UK time, Monday to Friday, excluding England and Wales bank holidays

We aim to acknowledge every request within one business day and to keep you updated until it is closed. We do not offer a contractual service level unless one is separately agreed in writing -- and we would rather say that plainly than publish a number we cannot hold to. If you need a contractual SLA, email legal@hisn.io and we will talk about it properly.

How we prioritise, in practice:

  • Something is broken for everyone -- searches failing, the daemon not starting, a licence rejecting a valid file. Worked on immediately, and you will hear from us the same working day.
  • Something is broken for one workflow, with a way around it. Worked on next, usually a fix in the following release.
  • A question, or something cosmetic. Answered within a few working days.

A security issue jumps all of this -- see below.

What Support Covers

Covered: installing, upgrading and configuring BabySOARus; the search commands, alert action, editor, tests, debugger and CI binary behaving as documented; licensing and licence import; anything the documentation says that turns out to be wrong.

Not covered (section 7.3 of the Terms of Service, and section 5 of the licence agreement): the code you write. BabySOARus is an execution engine; its purpose is to run Python and WebAssembly that you supply. We do not review, validate or debug your detections, and we have no access to them.

That said: if your code fails in a way that looks like our bug -- a sandbox limit that should not apply, a standard library module that should be present, an error that makes no sense -- send it. Telling those apart is our job, not yours, and we would rather look at ten of yours than miss one of ours.

Also not covered: Splunk itself, your data onboarding, your infrastructure, and versions of Splunk we do not support (see Requirements).

Reporting a Security Issue

Email security@hisn.io with what you found and how to reproduce it. We will acknowledge within one business day.

Please give us a reasonable chance to fix it before publishing. We will not threaten you, and we will credit you when it is fixed unless you would rather we did not.

Especially interested in: anything that escapes the WebAssembly sandbox, anything that reaches a network host the ACL should have denied, anything that lets guest code read a secret the host injects, and anything that lets a user act beyond their Splunk capabilities.

When a Licence Lapses

Not a support issue but the most likely surprise, so: an expired licence or trial degrades rather than stops. Searches keep running, nothing is deleted, and outbound network access from your code is denied. The Licensing documentation covers it in full, and section 6.3 of the licence agreement commits us not to make that behaviour more restrictive for a term already bought.


HISN.IO LTD, registered in England and Wales, company number 17215304. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.